Описание
Malicious Package in evil-package
All versions of evil-package contain malicious code. The package uploads the contents of process.env to example.com/log.
Recommendation
Remove the package from your environment. Given the host where the information was uploaded to there is no further indication of compromise.
Пакеты
Наименование
evil-package
npm
Затронутые версииВерсия исправления
>= 0.0.0
Отсутствует
Дефекты
CWE-506
Дефекты
CWE-506